Privacy Policy
Last updated: 4 September 2026
Brindavo LTD runs brindavo.com. To sell you something and get it to your door, we need some personal information; this policy explains what, why, who else sees it, how long we keep it, and what you can require us to do with it.
We process personal information under the UK General Data Protection Regulation, the Data Protection Act 2018 and, for cookies and marketing messages, the Privacy and Electronic Communications Regulations (PECR).
We don't sell your personal information, and we don't share it with other businesses for their own marketing.
1. Who's responsible
Brindavo LTD is the data controller for everything described on this page.
| Store | Brindavo, at brindavo.com |
| Company | Brindavo LTD |
| Address | Meadowhall Way, Sheffield S9 1EP, United Kingdom |
| support@brindavo.com | |
| Phone | +44 333 313 2000 |
| Customer service hours | Monday to Friday, 9:00 am–9:00 pm UK time |
| Response time | Within one working day |
Questions and requests about your data go to the email above with "Privacy" in the subject line.
2. What we collect, and where it comes from
From you, when you order: name, email address, phone number, billing and delivery address, the items you bought, and what happens to the order afterwards: delivery, returns, refunds.
From you, when you pay: your card number goes straight into the payment provider's secure form, never to us. We receive a confirmation, the card type and the last four digits.
From you, when you contact us: whatever you write, your email address, and any photographs you send with a return or complaint.
From you, if you open an account: email address, encrypted password, saved addresses and order history. Accounts are optional; guest checkout works the same way.
Automatically, when you browse: IP address, browser and device type, time zone, the page or search that brought you here, the pages and products you view, what goes in your basket, and whether you open our emails or click our adverts. This comes from cookies and similar technologies, most of which are set only with your consent (section 5).
From other companies: the payment provider tells us the outcome of its fraud check, the courier sends delivery status, and Shopify sends technical logs about how the shop is used.
We don't collect special category data (health, ethnicity, religion, sexual orientation and the like), and we ask you not to include it in messages to us.
3. Why we hold it, and the lawful basis
| Purpose | Lawful basis |
|---|---|
| Processing, dispatching and delivering your order; handling returns and refunds | Performance of a contract |
| Answering your questions and complaints | Performance of a contract |
| Running your account | Performance of a contract |
| Detecting and preventing fraud and misuse | Legitimate interests: protecting customers and the business |
| Keeping the site secure, fixing faults and understanding how it's used | Legitimate interests, and consent where cookies are involved |
| Sending marketing emails and texts | Consent, or the "soft opt-in" for existing customers (section 4) |
| Measuring and targeting advertising | Consent |
| Keeping accounting records | Legal obligation |
| Responding to lawful requests from authorities | Legal obligation |
Where we rely on legitimate interests, we've weighed our interest against your rights and concluded the processing is proportionate. You can object at any time (section 10). Where we rely on consent, you can withdraw it whenever you like without affecting anything done beforehand. Buying from us is never conditional on agreeing to marketing.
We don't make decisions about you that are based solely on automated processing and have legal or similarly significant effects. If the payment provider's fraud screening declines a transaction, a member of our team will review it if you contact us.
4. Marketing emails and texts
Order messages (confirmation, dispatch, delivery, refund) are sent because we need them to complete your purchase. They aren't marketing and unsubscribing doesn't stop them.
Marketing messages are sent in two situations. Either you've ticked the box to opt in, or you've bought from us and we email you about similar products under the PECR "soft opt-in", in which case you're given the chance to refuse when you order and in every message afterwards. Entering your phone number or email at checkout doesn't sign you up for marketing on its own.
If you've opted in to texts, they may include offers, basket reminders and new-product news. Message frequency varies, and your network's standard charges may apply. Reply STOP to any marketing text to opt out, or HELP for help.
To deliver these messages we share your name, contact details and order history with our email and messaging providers, for that purpose only.
Unsubscribe at any time using the link in any marketing email, by replying STOP to a text, or by emailing support@brindavo.com. It takes effect immediately.
5. Cookies
| Type | What it does | Set without consent? |
|---|---|---|
| Strictly necessary | Basket, checkout, login, security, remembering your cookie choice | Yes; the shop can't work without them |
| Functional | Remembers preferences such as region and currency | No |
| Analytics | Measures traffic, page performance and errors | No |
| Advertising | Measures our adverts and shows you relevant ones on other sites and social platforms | No |
Non-essential cookies are set only after you've consented through the cookie banner, as PECR requires. You can change or withdraw that consent at any time through the "Cookie preferences" link in the footer or in your browser settings. Blocking strictly necessary cookies will stop checkout from working.
Session cookies disappear when you close your browser; persistent cookies stay until they expire or you delete them.
6. Who else sees your information
Only the organisations that help us run the shop, and only what each one needs. Where they act on our behalf we have data processing agreements in place.
- Shopify, which hosts the shop and processes payments through Shopify Payments. For services that run across many shops, such as Shop Pay and Shopify's fraud protection, Shopify is itself a controller under its own privacy policy.
- Other payment providers you choose at checkout, such as Apple Pay or Google Pay, for payment and fraud screening
- Couriers and fulfilment partners, who receive your name, address, phone number and email to deliver the parcel and send updates
- Email and messaging providers, for order messages and marketing you've agreed to
- Analytics and advertising partners, such as Google and Meta, when your cookie consent allows it
- Accountants, auditors, solicitors and IT providers, for the records and systems the business needs
- HMRC, regulators, the police and courts, where the law requires it
We also disclose information to comply with a legal obligation, respond to a lawful request from a public authority, protect our legal rights, or prevent fraud and security threats. If the business is sold, merged or restructured, customer records transfer with it and the new owner takes on the obligations in this policy.
7. Advertising
With your consent, we use information about your visits to show you relevant adverts on platforms such as Google, Facebook and Instagram, and to measure whether our adverts work. This relies on advertising cookies and, where you've agreed, a hashed version of your email address matched by the platform.
You can withdraw consent at any time through the cookie banner. You can also opt out of interest-based advertising across many platforms at youronlinechoices.com.
8. Information leaving the UK
Some of our providers process personal information outside the United Kingdom: Shopify and our advertising and analytics partners in the United States and Canada, and our fulfilment partners in the countries where orders are dispatched from.
Where a transfer is a restricted transfer under UK data protection law, we rely on UK adequacy regulations where they exist, and otherwise on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any additional safeguards needed. If you'd like to know which mechanism applies to a particular provider, ask us.
9. How long we keep it
| Information | Kept for |
|---|---|
| Orders, invoices and payment confirmations | 6 years from the end of the financial year, for HMRC |
| Return and complaint records | Until closed, then for as long as a claim could be brought (up to 6 years) |
| Account | Until you close it, or after 3 years without a login |
| Marketing subscription | Until you unsubscribe; we keep the unsubscribe itself so we don't email you by mistake |
| Support correspondence | 2 years after the last message |
| Analytics and advertising data | Up to 26 months, less where the tool allows |
| Fraud and security logs | 12 months |
While a dispute or legal claim is open, the relevant records stay. After the retention period, information is deleted, anonymised or securely destroyed.
10. Your rights
Under UK data protection law you can ask us to:
- give you access to the personal information we hold about you, and a copy of it
- correct anything inaccurate or incomplete
- erase it, where we're not required to keep it
- restrict how we process it while a dispute is resolved
- provide it in a portable format where we process it by automated means on the basis of contract or consent
- stop processing based on legitimate interests, and always stop direct marketing, if you object
- stop relying on your consent, which you can withdraw at any time
Some of these rights carry conditions and exemptions; we'll explain if one applies.
To exercise a right, email support@brindavo.com. We may ask you to confirm your identity, usually by checking details of a recent order. We respond within one month. Complex requests may take up to two months longer, and we'll tell you within the first month if that applies. There's no charge, and using these rights won't change how we treat you.
11. Security
All traffic to and from the shop is encrypted (TLS). Card details never reach our systems, because payment is handled by PCI DSS-compliant providers. Access to customer information is limited to the people who need it for their work and protected by two-factor authentication.
No online service can guarantee absolute security, and we won't claim otherwise. If a breach is likely to pose a risk to your rights, we'll report it to the Information Commissioner's Office within 72 hours, and where the risk is high, we'll tell you directly without undue delay.
12. Children
The shop is intended for adults. We don't knowingly collect personal information from children under 13, and we remove it if we learn we have. If you believe a child has given us their details, email us.
13. Other people's websites
Links on our site, including courier tracking pages and payment providers, lead to sites we don't control. Their privacy notices apply there, not ours.
14. Complaints
Raise it with us first at support@brindavo.com. We acknowledge complaints within five working days and aim to resolve them within a month.
If our response doesn't satisfy you, you have the right to complain to the UK supervisory authority:
Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF 0303 123 1113 · ico.org.uk
15. Changes to this policy
We update this policy when our practices, our providers or the law change. The current version is always on this page with the date at the top. Where a change materially affects how we handle your information, we'll tell you by email or on the site before it takes effect.
16. Contact
Brindavo LTD Meadowhall Way, Sheffield S9 1EP, United Kingdom support@brindavo.com · +44 333 313 2000 Monday to Friday, 9:00 am–9:00 pm UK time · Replies within one working day